[Zeek] tcmalloc large alloc

Seth Hall seth at corelight.com
Wed Mar 27 10:56:57 PDT 2019



On 27 Mar 2019, at 11:54, Zander Work wrote:

> The first two showing ??:0 makes sense b/c those are memory addresses. 
> It looks like the PE analyzer might be the culprit but I'm not sure.

Yep, I knew the first two would look like that.  It's ASLR being applied 
to glibc function (which is fine and not what I was interested in 
anyway).  It did end up showing what I expected it to.  I'll look around 
a little bit and see if anything makes sense.

Thanks!
   .Seth

--
Seth Hall * Corelight, Inc * www.corelight.com


More information about the Zeek mailing list